5 ms·
First, auditing the hundreds of millions of lines of code that it takes to build an OS and userspace every election and midterm is completely unrealistic. Espe
by badsock 10y ago
First, auditing the hundreds of millions of lines of code that it takes to build an OS and userspace every election and midterm is completely unrealistic. Especially given the degree of code obfuscation that is possible.
Second, at the silicon level there's billions of transistors in a CPU, silicon in general is prohibitively expensive to audit, and you can do malicious things by just putting in nigh-undetectable changes in dopant levels:
https://www.schneier.com/blog/archives/2013/09/surreptitiously.html https://www.schneier.com/blog/archives/2013/09/surreptitious...
Third: you don't need to hide the hack forever. You just need to gain enough power in the election that you can suppress any further investigation.
Given the parade of hacks that make the HN front page every week, at all levels of government and industry, given that the well-funded and incredibly paranoid US military inadvertently deployed backdoored chips, given that existing voting machines have had demonstrable amateur-hour exploits in them:
http://fortune.com/2016/11/04/voting-machine-hack-watch-video-cylance/ http://fortune.com/2016/11/04/voting-machine-hack-watch-vide...
http://www.pcworld.com/article/135461/article.html http://www.pcworld.com/article/135461/article.html
is it really that difficult to believe that voting machines can be hacked?